Description
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.8.1, internal/cookies.ParseCookies in internal/cookies/cookies.go handles boundary ASCII control characters and control-only or empty cookie names differently from several backend cookie parsers. An unauthenticated attacker can craft a Cookie header so Coraza indexes or drops a cookie under a different name or value from the backend application, causing rules targeting REQUEST_COOKIES or REQUEST_COOKIES_NAMES to miss application-visible attacker data. Exploitation depends on the backend parser and affected rule scope, and interior control characters with inconsistent backend behavior are outside this advisory's remediation. This issue is fixed in version 3.8.1.
Published: 2026-10-09
Score: 4 Medium
EPSS: n/a
KEV: No
Impact: Rule bypass via cookie parsing confusion
Action: Update
AI Analysis

Impact

An unauthenticated attacker can construct a Cookie header containing boundary ASCII control characters that cause the Coraza cookie parser to index or drop cookie names in a manner inconsistent with the application’s backend parser. This discrepancy enables the attacker to make REQUEST_COOKES or REQUEST_COOKIES_NAMES rules miss the attacker’s data, effectively bypassing security checks that rely on accurate cookie extraction. The flaw stems from the internal : cookies.ParseCookies function handling control characters differently than several backend parsers and is a product of improper input validation (CWE‑436).

Affected Systems

The vulnerability affects the OWASP Coraza WAF library, specifically versions earlier than 3.8.1. Users running any Coraza deployments that rely on the internal cookie parser before the 3.8.1 release are exposed to this flaw.

Risk and Exploitability

The severity as scored by CVSS is 4, indicating moderate impact. The EPSS score is not available and the vulnerability is not currently listed in CISA’s KEV catalog. Exploitation requires the attacker to send a crafted HTTP request with the confusing cookie header; it does not require authentication and does not provide code execution or other privilege escalation. The likelihood of exploitation is moderate to low, but the potential to bypass key WAF rules warrants timely remediation.

Generated by OpenCVE AI on October 9, 2026 at 19:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Coraza WAF to version 3.8.1 or later, which contains the fixed cookie parser logic.
  • Review and, if possible, supplement your security policy to protect against missing or misidentified cookie data, for example by adding supplemental checks on request body or other headers.
  • If an immediate patch is not feasible, restrict incoming Cookie headers to exclude boundary ASCII control characters or apply application-level sanitization that aligns with the backend cookie parser.

Generated by OpenCVE AI on October 9, 2026 at 19:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 09 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.8.1, internal/cookies.ParseCookies in internal/cookies/cookies.go handles boundary ASCII control characters and control-only or empty cookie names differently from several backend cookie parsers. An unauthenticated attacker can craft a Cookie header so Coraza indexes or drops a cookie under a different name or value from the backend application, causing rules targeting REQUEST_COOKIES or REQUEST_COOKIES_NAMES to miss application-visible attacker data. Exploitation depends on the backend parser and affected rule scope, and interior control characters with inconsistent backend behavior are outside this advisory's remediation. This issue is fixed in version 3.8.1.
Title OWASP Coraza WAF: Cookie Parser Confusion
Weaknesses CWE-436
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T18:24:00.100Z

Reserved: 2026-10-08T22:34:49.289Z

Link: CVE-2026-107835

cve-icon Vulnrichment

Updated: 2026-10-09T18:23:36.147Z

cve-icon NVD

Status : Received

Published: 2026-10-09T18:17:05.157

Modified: 2026-10-09T19:16:41.780

Link: CVE-2026-107835

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T19:30:11Z

Weaknesses